CVE-2021-3468
published 2021-06-02CVE-2021-3468: A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.45%
36.7th percentile
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avahi | avahi | — | — |
| avahi | avahi | >= 0 < 0.8-5+deb11u2 | 0.8-5+deb11u2 |
| avahi | avahi | >= 0 < 0.8-7 | 0.8-7 |
| avahi | avahi | >= 0 < 0.8-7 | 0.8-7 |
| avahi | avahi | >= 0 < 0.8-7 | 0.8-7 |
| avahi | avahi | >= 0 < 0.7-3.1ubuntu1.3 | 0.7-3.1ubuntu1.3 |
| avahi | avahi | >= 0 < 0.7-4ubuntu7.1 | 0.7-4ubuntu7.1 |
| avahi | avahi | 0.6 – 0.8 | — |
| debian | avahi | < avahi 0.8-7 (bookworm) | avahi 0.8-7 (bookworm) |
| debian | debian_linux | — | — |
| msrc | azl3_avahi_0.8-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_avahi_0.8-5_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_avahi_0.8-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-43rm-fv4g-cmj8: A flaw was found in avahi in versions 0
ghsa_unreviewed·2022-05-24
CVE-2021-3468 [MEDIUM] CWE-835 GHSA-43rm-fv4g-cmj8: A flaw was found in avahi in versions 0
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.
OSV
avahi vulnerabilities
osv·2021-07-07·CVSS 5.5
CVE-2021-3468 [MEDIUM] avahi vulnerabilities
avahi vulnerabilities
Thomas Kremer discovered that Avahi incorrectly handled termination signals
on the Unix socket. A local attacker could possibly use this issue to cause
Avahi to hang, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 20.10. (CVE-2021-3468)
It was discovered that Avahi incorrectly handled certain hostnames. A local
attacker could possibly use this issue to cause Avahi to crash, resulting
in a denial of service. This issue only affected Ubuntu 20.10 and Ubuntu
21.04. (CVE-2021-3502)
OSV
CVE-2021-3468: A flaw was found in avahi in versions 0
osv·2021-06-02·CVSS 5.5
CVE-2021-3468 [MEDIUM] CVE-2021-3468: A flaw was found in avahi in versions 0
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.
Ubuntu
Avahi vulnerabilities
vendor_ubuntu·2021-07-07·CVSS 5.5
CVE-2021-3468 [MEDIUM] Avahi vulnerabilities
Title: Avahi vulnerabilities
Summary: Several security issues were fixed in Avahi.
Thomas Kremer discovered that Avahi incorrectly handled termination signals
on the Unix socket. A local attacker could possibly use this issue to cause
Avahi to hang, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 20.10. (CVE-2021-3468)
It was discovered that Avahi incorrectly handled certain hostnames. A local
attacker could possibly use this issue to cause Avahi to crash, resulting
in a denial of service. This issue only affected Ubuntu 20.10 and Ubuntu
21.04. (CVE-2021-3502)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Avahi vulnerability
vendor_ubuntu·2021-07-07
CVE-2021-3468 Avahi vulnerability
Title: Avahi vulnerability
Summary: Avahi could be made to denial of service if it received a specially crafted input.
USN-5008-1 fixed a vulnerability in avahi. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Thomas Kremer discovered that Avahi incorrectly handled termination signals
on the Unix socket. A local attacker could possibly use this issue to cause
Avahi to hang, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function all
vendor_msrc·2021-06-08·CVSS 5.5
CVE-2021-3468 [MEDIUM] CWE-835 A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function all
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service which becomes unresponsive after this flaw is triggered.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed
Red Hat
avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket
vendor_redhat·2021-03-10·CVSS 5.5
CVE-2021-3468 [MEDIUM] CWE-835 avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket
avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.
A flaw was found in avahi. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi servic
Debian
CVE-2021-3468: avahi - A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal th...
vendor_debian·2021·CVSS 5.5
CVE-2021-3468 [MEDIUM] CVE-2021-3468: avahi - A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal th...
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.
Scope: local
bookworm: resolved (fixed in 0.8-7)
bullseye: resolved (fixed in 0.8-5+deb11u2)
forky: resolved (fixed in 0.8-7)
sid: resolved (fixed in 0.8-7)
trixie: resolved (fixed in 0.8-7)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1939614https://lists.debian.org/debian-lts-announce/2022/06/msg00009.htmlhttps://lists.debian.org/debian-lts-announce/2023/06/msg00028.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1939614https://lists.debian.org/debian-lts-announce/2022/06/msg00009.htmlhttps://lists.debian.org/debian-lts-announce/2023/06/msg00028.html
2021-06-02
Published